Fix CSRF token handling and update fetch URL for push subscription
Some checks failed
Scan for leaked secrets using Kingfisher / kingfisher-secrets-scan (push) Has been cancelled
Some checks failed
Scan for leaked secrets using Kingfisher / kingfisher-secrets-scan (push) Has been cancelled
This commit is contained in:
@@ -42,7 +42,7 @@
|
||||
|
||||
<script>
|
||||
const vapidKey = "{{ config('webpush.vapid.public_key') }}";
|
||||
// const csrfToken = "{{ csrf_token() }}";
|
||||
const csrfToken = "{{ csrf_token() }}";
|
||||
|
||||
async function registerPush() {
|
||||
if (!('serviceWorker' in navigator)) return;
|
||||
@@ -57,11 +57,11 @@
|
||||
applicationServerKey: vapidKey
|
||||
});
|
||||
|
||||
await fetch('/api/push/subscribe', {
|
||||
await fetch('/push/subscribe', {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
// 'X-CSRF-TOKEN': csrfToken
|
||||
'X-CSRF-TOKEN': csrfToken
|
||||
},
|
||||
body: JSON.stringify(subscription)
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user